Threats Feed|MuddyWater|Last Updated 26/08/2026|AuthorCertfa Radar|Publish Date07/12/2018

Spear-Phishing and POWERSTAT: Dissecting MuddyWater's Latest Middle East Attacks

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Downloader,Dropper,Malicious Macro,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: Low Impact/Low Probability

Threat Overview

In late November 2018, the Iranian APT group MuddyWater launched a new series of attacks in Middle East countries, targeting Lebanon, Oman, and Turkey. The campaign, consistent with their previous tactics since 2017, utilized spear-phishing emails with blurred documents to trick victims into enabling VB-macro code, subsequently infecting hosts with POWERSTAT malware. The attack involved creating a malicious Excel document for downloading further payloads, using PowerShell and JavaScript for execution delays, and establishing persistence through registry modifications and scheduled tasks. The POWERSTAT backdoor facilitated data exfiltration and remote command execution, highlighting MuddyWater's continued reliance on scripting languages and system tools for their objectives.

Detected Targets

TypeDescriptionConfidence
RegionLebanon
Verified
RegionOman
Verified
RegionTurkey
Verified

Extracted IOCs

  • amorenvena[.]com
  • amphira[.]com
  • pazazta[.]com
  • 077bff76abc54edabda6b7b86aa1258fca73db041c53f4ec9c699c55a0913424
  • 294a907c27d622380727496cd7c53bf908af7a88657302ebd0a9ecdd30d2ec9d
  • 79f2d06834a75981af8784c2542e286f1ee757f7a3281d3462590a89e8e86b5a
  • ae2c0de026d0df8093f4a4e2e2e4d297405f943c42e86d3fdd0ddea656c5483d
  • ccfdfcee9f073430cd288522383ee30a7d6d3373b968f040f89ae81d4772a7d0
  • 139[.]162.245.200
  • hxxp://amphira[.]com
  • hxxp://pazazta[.]com/app/icon.png
  • hxxps://amorenvena[.]com
download

Tip: 12 related IOCs (1 IP, 3 domain, 3 URL, 0 email, 5 file hash) to this threat have been found.

Overlaps

MuddyWaterMuddyWater Espionage Campaign: A Deep Dive into Malware and Tactics

Source: Picussecurity - March 2022

Detection (one case): 294a907c27d622380727496cd7c53bf908af7a88657302ebd0a9ecdd30d2ec9d

MuddyWaterMuddyWater Expands Cyberattacks with Two-Stage Spear-phishing Campaign Targeting Lebanon and Oman

Source: ClearSky - November 2018

Detection (five cases): hxxp://pazazta[.]com/app/icon.png, 294a907c27d622380727496cd7c53bf908af7a88657302ebd0a9ecdd30d2ec9d, amorenvena[.]com, amphira[.]com, pazazta[.]com

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

MuddyWater Cyberattack Campaign

A targeted cyberattack campaign was detected utilizing malicious document attachments to infect organizations with a backdoor program called POWERSTAT. The attackers used blurred document previews to trick recipients into enabling embedded macros, initiating a multi-stage infection sequence.

The campaign was conducted by an Iranian threat group known as "MuddyWater," which has been active since at least 2017. The group is recognized for targeted cyber operations in the Middle East, frequently employing social engineering tactics and macro-based document lures.

The primary goal was to establish persistent access on compromised target machines to gather intelligence and execute remote commands. The attackers sought to monitor compromised systems, run scripts, and exfiltrate operational details.

This was a targeted cyber attack rather than a widespread campaign aimed at the general public. The targeting specifically focused on institutional entities located in Lebanon, Oman, and Turkey.

Institutional targets hold strategic geopolitical data and organizational intelligence. Establishing long-term foothold access inside these systems allows foreign threat actors to conduct ongoing monitoring and data collection.

Victims received spear-phishing emails containing blurred Word files, such as fake resume documents. Once the victim enabled macros, the document displayed a fake software error message while secretly executing background scripts to download and run the POWERSTAT backdoor malware.

Organizations should block macro execution by default, monitor system execution tools like PowerShell and CSCRIPT, and block known malicious domains and IP addresses. Individuals should avoid enabling macros on unexpected email attachments and report unusual document behavior to IT security teams.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights